snowsoftware records
12 published records for vendor snowsoftware.
Researcher profile
- Entered KEV
- 1 · 8.3%
- Weaponized
- 1 · 8.3%
- Pre-auth RCE
- 1
- With a fix record
- 25%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-269 Improper Privilege Management1
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-428 Unquoted Search Path or Element1
- CWE-64 Windows Shortcut Following (.LNK)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
35Monitor | CVE-2024-4129No exploit | Authentication bypass in Snow License Managersnow software ab · snow license manager · CWE-287 | High8.8 | — | 0.5% | May 14, 2024 |
31Monitor | CVE-2021-27579No exploit | Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across ansnowsoftware · snow inventory agent | High7.8 | — | 0.5% | Feb 23, 2021 |
31Monitor | CVE-2021-4106No exploit | Vulnerability in Snow Inventory Java Scannersnowsoftware · snow inventory java scanner · CWE-691 | High7.8 | — | 0.3% | Feb 16, 2022 |
31Monitor | CVE-2022-0883No exploit | Windows Unquoted/Trusted Service Pathssnowsoftware · snow license manager · CWE-428 | High7.8 | — | 0.2% | May 18, 2022 |
28Monitor | CVE-2023-3864No exploit | SQL injection vulnerability in Snow License Managersnowsoftware · snow license manager · CWE-89 | High7.2 | — | 0.6% | Aug 11, 2023 |
24Monitor | CVE-2021-41562No exploit | Deletion of arbitrary files vulnerability in Snow Agent for Windowssnowsoftware · snow inventory agent · CWE-64 | Medium6.1 | — | 0.3% | Nov 3, 2021 |
22Monitor | CVE-2023-7169No exploit | Impersonate vendor signed Powershell scriptssnowsoftware · snow inventory agent · CWE-290 | Medium5.5 | — | 0.2% | Feb 8, 2024 |
22Monitor | CVE-2024-1149No exploit | Improper validation of update packagessnowsoftware · snow inventory agent · CWE-347 | Medium5.5 | — | 0.1% | Feb 8, 2024 |
22Monitor | CVE-2024-1150No exploit | Improper validation of update packagessnowsoftware · snow inventory agent · CWE-347 | Medium5.5 | — | 0.1% | Feb 8, 2024 |
19Monitor | CVE-2023-3937No exploit | Cross site scripting vulnerabilities in Snow License Managersnowsoftware · snow license manager · CWE-79 | Medium4.8 | — | 0.3% | Aug 11, 2023 |
17Monitor | CVE-2023-2679No exploit | Data leakage in Adobe connector for SPE edition of SLMsnowsoftware · snow license manager · CWE-269 | Medium4.3 | — | 0.4% | May 17, 2023 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2024-412935Monitor
Authentication bypass in Snow License Manager
HighCVSS 8.8No exploitEPSS 0%snow software ab · snow license managerMay 14, 2024
- CVE-2021-2757931Monitor
Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across an
HighCVSS 7.8No exploitEPSS 0%snowsoftware · snow inventory agentFeb 23, 2021
- CVE-2021-410631Monitor
Vulnerability in Snow Inventory Java Scanner
HighCVSS 7.8No exploitEPSS 0%snowsoftware · snow inventory java scannerFeb 16, 2022
- CVE-2022-088331Monitor
Windows Unquoted/Trusted Service Paths
HighCVSS 7.8No exploitEPSS 0%snowsoftware · snow license managerMay 18, 2022
- CVE-2023-386428Monitor
SQL injection vulnerability in Snow License Manager
HighCVSS 7.2No exploitEPSS 1%snowsoftware · snow license managerAug 11, 2023
- CVE-2021-4156224Monitor
Deletion of arbitrary files vulnerability in Snow Agent for Windows
MediumCVSS 6.1No exploitEPSS 0%snowsoftware · snow inventory agentNov 3, 2021
- CVE-2023-716922Monitor
Impersonate vendor signed Powershell scripts
MediumCVSS 5.5No exploitEPSS 0%snowsoftware · snow inventory agentFeb 8, 2024
- CVE-2024-114922Monitor
Improper validation of update packages
MediumCVSS 5.5No exploitEPSS 0%snowsoftware · snow inventory agentFeb 8, 2024
- CVE-2024-115022Monitor
Improper validation of update packages
MediumCVSS 5.5No exploitEPSS 0%snowsoftware · snow inventory agentFeb 8, 2024
- CVE-2023-393719Monitor
Cross site scripting vulnerabilities in Snow License Manager
MediumCVSS 4.8No exploitEPSS 0%snowsoftware · snow license managerAug 11, 2023
- CVE-2023-267917Monitor
Data leakage in Adobe connector for SPE edition of SLM
MediumCVSS 4.3No exploitEPSS 0%snowsoftware · snow license managerMay 17, 2023